Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ilovecheckpoint
Participant

ldap communication has stop to work

I have noticed randomly, ldap communication to AD does not work anymore.

Synthoms are the followings:

selecting Ldap account unity property:

Fetch branches: Failed to connect to LDAP Server. Please ensure that the administrator's credentials are correct and try again

If I enable ldaps, the fingerprint fetch does not work.

Account role: when I try to add a user: errore retreiving results

I have checked and updated the AD account and it did not solve the problem.

Communication from management server and from the gateway to AD is opened.

Does exists an exaustive guide on troubleshooting the problem?

Ideally, I would like to automatize a check ldap and ldaps every day to be sure there is no problem.

 

0 Kudos
4 Replies
simonemantovani
MVP Diamond
MVP Diamond

If you can use LDAP in clear text, try to perform a capture with tcpdump between managemen server and LDAP server, so it will be possible to verify possible issues.

0 Kudos
Lesley
MVP Platinum
MVP Platinum

Do you have this issues on all DC servers that you connect with? Do you use IDC? (please note: Check Point recommends to use Identity Collector as the Identity Source instead of AD Query.)

You can use the build on tool for further debugging: https://support.checkpoint.com/results/sk/sk100406

What is output during issue: adlog a dc

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Where possible please confirm the details of the version / JHF levels and Windows server versions involved.

CCSM R77/R80/ELITE
0 Kudos
spottex
Collaborator

If the AD team recently updated their AD cert, they need to provide the new Cert MD5 fingerprint so you can add it and retest the fetch query

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events